Vulnerability record · CVE-2016-0956 · published 10 February 2016
CVE-2016-0956: Apache Sling Servlets Post information disclosure in Adobe Experience Manager
Apache · Sling
The Servlets Post component 2.3.6 in Apache Sling, as bundled in Adobe Experience Manager 5.6.1, 6.0.0 and 6.1.0, exposes sensitive information to remote attackers through unspecified vectors. The flaw is a CWE-200 information exposure reachable over the network without credentials, so any reachable AEM instance running the affected Sling version is at risk. The record does not describe the exact request or data leaked, so defenders must rely on the vendor advisory and patch rather than a precise trigger.
Description
The Servlets Post component 2.3.6 in Apache Sling, as used in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0, allows remote attackers to obtain sensitive information via unspecified vectors.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityUnauthenticated remote information disclosure with high confidentiality impact, public exploit code and very high EPSS, though no KEV listing or active exploitation is documented.
What it is
The Servlets Post component 2.3.6 in Apache Sling, as bundled in Adobe Experience Manager 5.6.1, 6.0.0 and 6.1.0, exposes sensitive information to remote attackers through unspecified vectors. The flaw is a CWE-200 information exposure reachable over the network without credentials, so any reachable AEM instance running the affected Sling version is at risk. The record does not describe the exact request or data leaked, so defenders must rely on the vendor advisory and patch rather than a precise trigger.
Impact
An unauthenticated remote attacker can read sensitive information from the affected AEM/Sling deployment, with high confidentiality impact and no integrity or availability effect. The specific data exposed is not stated in the record.
Attack surface
Reachable over the network via HTTP against the Sling Servlets Post component; the CVSS vector shows no privileges and no user interaction required. No authentication is needed per the vector, though the exact endpoint is not specified.
Exploitation
Not listed in CISA KEV and no ransomware association is documented. EPSS is high (0.51151, ~98.9th percentile) and a public Exploit-DB entry (39435) plus Packet Storm and Full Disclosure posts exist, indicating public proof-of-concept material is available.
What to do
- Apply the Adobe Experience Manager fix referenced in Adobe advisory APSB16-05 (helpx.adobe.com/security/products/experience-manager/apsb16-05.html) or upgrade the bundled Apache Sling Servlets Post component past 2.3.6.
- If immediate patching is not possible, restrict network access to AEM/Sling instances to trusted networks and block unnecessary exposure of the Servlets Post endpoints.
- Review and disable or restrict the Servlets Post component if it is not required by the application.
- Monitor vendor advisories for the affected AEM versions (5.6.1, 6.0.0, 6.1.0) and confirm which deployments still run them.
Detection
- Inspect web/proxy logs for anomalous requests to Sling Servlets Post paths returning larger-than-normal or unexpected response bodies.
- Alert on unauthenticated access to Sling servlet endpoints from external or untrusted source addresses.
- Compare responses from the affected component against expected content to identify unexpected data disclosure.
- Track AEM/Sling version banners and asset inventories to flag hosts still running the affected versions.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2016-0956 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-0956), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.